Malicious domain monitoring and filtering using drift monitoring and contextual data
Abstract
Example embodiments of the present disclosure provide for an example method including generating a baseline set of domains by comparing domains of interest to a group of existing registered domains. The domains of interest are generated using a permutation engine based on a first domain. The example method includes periodically generating a dynamic set of domains by comparing the domains of interest to an updated group of existing registered domains. The updated group is obtained in real-time. The example method includes determining a potentially malicious domain based on comparing the baseline set and dynamic set. The example method includes for each respective potentially malicious domain: obtaining an IP address associated with the potentially malicious domain and determining an IP address risk score. The example method includes determining a potentially malicious domain is a malicious domain based on the IP address risk score of the potentially malicious domain.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
generating a baseline set of domains by comparing a plurality of domains of interest to a group of existing registered domains, wherein the domains of interest are generated using a permutation engine based on a first domain; periodically generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time; determining at least one potentially malicious domain based on comparing the baseline set and dynamic set; for each respective potentially malicious domain:
obtaining an internet protocol (IP) address associated with the potentially malicious domain;
determining a risk score for the respective potentially malicious domain by:
identifying one or more other different domains associated with the IP address by selecting a pre-defined number of domains associated with the IP address based on a domain registration date; and
determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address; and
determining a first potentially malicious domain is a malicious domain based on the risk score of the first potentially malicious domain.
2 . The computer-implemented method of claim 1 , comprising:
automatically initiating a domain takedown action in response to determining the first potentially malicious domain is a malicious domain.
3 . The computer-implemented method of claim 1 , wherein identifying the one or more other different domains associated with the IP address comprises selecting a random subset of domains.
4 . The computer-implemented method of claim 1 , wherein identifying the one or more other different domains associated with the IP address comprises selecting a random subset of domains, wherein the random subset of domains comprises a pre-defined number of domains.
5 . The computer-implemented method of claim 1 , wherein determining the first potentially malicious domain is a malicious domain is based on the risk score of the first potentially malicious domain satisfying a criterion related to a threshold risk score.
6 . The computer-implemented method of claim 1 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:
obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and summing the obtained domain risk scores for each respective domain of the one or more other different domains.
7 . The computer-implemented method of claim 1 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:
obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address.
8 . The computer-implemented method of claim 7 , wherein generating the weighted average of the domain risk scores for each respective domain of the one or more other different domains, comprises weighting more recently registered domain risk scores more heavily than earlier registered domain risk scores.
9 . A computing system, comprising:
one or more processors; and one or more computer-readable media storing instructions that are executable to cause the one or more processors to perform operations, the operations comprising: obtaining a first domain; generating, using a permutation engine, a plurality of domains of interests; generating a baseline set of domains by comparing the plurality of domains of interest to a group of registered domains, wherein the baseline set comprises at least a domain and an internet protocol (IP) address; periodically, generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time; comparing, in response to generating the dynamic set of domains, the dynamic set to the baseline set to determine changes to at least one of the group of domains or an IP address for a domain being updated; detecting, based on the comparison of the baseline set and the dynamic set, creation or deletion of one or more potentially malicious domains; for each respective potentially malicious domain:
obtaining the IP address associated with the potentially malicious domain;
determining a risk score for the respective potentially malicious domain by:
identifying one or more other different domains associated with the IP address; and
determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address by:
obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and
generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address; and
determining a potentially malicious domain is a malicious domain based on the risk score.
10 . The computing system of claim 9 , wherein generating the dynamic set of domains occurs multiple times a day.
11 . The computing system of claim 9 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:
obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address.
12 . The computing system of claim 11 , wherein generating the weighted average of the domain risk scores for each respective domain of the one or more other different domains, comprises weighting more recently registered domain risk scores more heavily than earlier registered domain risk scores.
13 . The computing system of claim 9 , wherein identifying one or more other different domains associated with the IP address comprises selecting a random subset of domains, wherein the random subset of domains comprises a pre-defined number of domains.
14 . The computing system of claim 9 , wherein identifying one or more other different domains associated with the IP address comprises selecting a pre-defined number of domains.
15 . The computing system of claim 14 , wherein the pre-defined number of domains are selected based on a domain registration date.
16 . The computing system of claim 9 , comprising:
automatically initiating a domain takedown action in response to determining the potentially malicious domain is a malicious domain.
17 . One or more non-transitory computer readable media storing instructions that are executable by one or more processors to perform operations comprising:
generating a baseline set of domains by comparing a plurality of domains of interest to a group of existing registered domains, wherein the domains of interest are generated using a permutation engine based on a first domain; periodically generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time; determining at least one potentially malicious domain based on comparing the baseline set and dynamic set; for each respective potentially malicious domain:
obtaining an IP address associated with the potentially malicious domain;
determining a risk score for the respective potentially malicious domain by:
identifying one or more other different domains associated with the IP address; and
determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address by:
obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and
generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address; and
determining a first potentially malicious domain is a malicious domain based on the risk score of the first potentially malicious domain.Join the waitlist — get patent alerts
Track US12542800B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.